Skip to main content
Emerging ThreatsData Breaches

Valve Exposes Steam Hardware Customer Data Breach

Rows of shelving and shipping containers in a brightly-lit logistics warehouse with crates and a shipping label printer on…

"Between July 29 2026 and August 1, 2026, a cyberattack hit CEVA Logistics, the company that ships Steam hardware to customers in Europe," Valve wrote in breach-notification e‑mails to affected customers.

CEVA Logistics: timeline, scale and role

Valve says the intrusion gave attackers access to CEVA Logistics' servers between July 29 and August 1, 2026. CEVA is identified in Valve's notice as the company that ships Steam hardware to customers in Europe; it is a fully owned subsidiary of the CMA CGM Group. The source material notes CEVA operates roughly 1,000 warehouses, handled 15 million shipments last year, and the CMA CGM Group reported $18.3 billion in revenues in 2025.

Stolen fields: names, addresses, phone numbers, emails, and order details

According to Valve's message, the attackers accessed the delivery-related information CEVA receives in order to ship hardware orders. Valve lists the likely compromised data fields as the affected individuals' names, addresses, phone numbers, e‑mail addresses, and the type and price of ordered products. Valve explicitly stated that CEVA does not have access to payment information, passwords, Steam Guard codes, or other sensitive Steam account data, and that those categories were not impacted.

Valve's customer notice and phishing warning

Valve told customers it learned of the CEVA breach on August 7 and began notifying customers in Europe whose delivery records CEVA retains. "Because CEVA retains this information for up to 90 days after that order, we are sending this message to all customers we can assume were impacted," Valve wrote in the e‑mail messages that appeared in customers' inboxes.

Valve warned recipients to expect targeted fraud using the stolen delivery details. "They may quote your address back to you to prove they're genuine. They may ask you to confirm a delivery, pay a small customs or redelivery fee, or sign in somewhere to 'verify' your order. Treat all of them as fake," the notice said. Valve advised that affected customers do not need to change their Steam password or adjust account settings as a result of this incident.

Operational disruption: eight warehouses and retail notifications

The disclosure follows a separate notice from CEVA to multiple European retailers on August 1 that a cyberattack had disrupted operations at eight of its European warehouses. Valve said CEVA has isolated the affected systems, taken them offline, and brought in outside investigators. Valve added it is pressing CEVA for the full scope of what was taken and how the intrusion occurred, and that Valve is in the process of notifying the data protection authorities in the countries affected.

What this means for Steam hardware customers, European retailers, and delivery partners

  • Steam hardware customers: Those named in Valve's notice should anticipate targeted scams that use accurate delivery details. Valve's advisory specifically warns of e‑mail, SMS, or voice phishing that may impersonate Steam, Valve, or delivery companies and may cite the customer's address to appear legitimate.
  • European retailers: CEVA informed multiple retailers on August 1 about disruptions at eight warehouses; retailers who rely on CEVA for distribution will be watching CEVA's ongoing investigation and any follow‑up notices about shipment integrity and customer data exposure.
  • CEVA and delivery partners: CEVA has isolated affected systems and engaged outside investigators; the company will be the primary source for the technical scope of the intrusion, which Valve says it is continuing to press CEVA to provide.

Valve's notice leaves two concrete near‑term actions on the record: customers should treat unsolicited delivery‑related contact as fraudulent, and Valve and CEVA are conducting parallel notification and investigative steps while regulators are being informed. Valve also indicated a practical limit on exposure by clarifying CEVA's lack of access to payment credentials and Steam account secrets — even as it acknowledged that attackers obtained the shipment details that enable convincing, targeted fraud.

CEVA's role as a large logistics operator for Steam hardware and the confirmed window of server access make the next public disclosures — CEVA's investigative findings and regulator filings — the critical items for affected customers and partners to watch.

Source: BleepingComputer — Valve notifies Steam hardware customers of a data breach